In 1988, I was paid to write a few lines of code. A few years later, I was paid to fix those same lines. That was my contribution to the Y2K bug, and I don’t feel bad about it at all. Back in high school, there was a kid I didn’t like who asked me to help him with our upcoming AP Calc test.

I told him I’d copy my program over to his calculator and took it home for the weekend, explaining that it would take a while. The whole thing was just ten lines: print “I don’t like you” and then go back to that line. When he ran it, the calculator got stuck in an endless loop of insults until he finally pulled the batteries out. During sixth form, surrounded by a bunch of idiots, I wrote a program that would spam-launch the Explorer window.
It was a throwback to the days when people would spam the Explorer button on the school keyboards during IT lessons. The first person who fell for it spread it around our group, and it caused a lot of computer crashes. I narrowly avoided getting in trouble because the version that got sent around wasn’t exactly the one I created. I’m a novice programmer at best.
One of the programs we use at work was built by a contractor who hard-coded dates into the code instead of using a formula based on the current date. As soon as we need dates past 2022, the program will error out. The date codes need to be replaced or fixed in at least a dozen places, which might be more work than we want to do. I don’t know, it’s not my department.
Most dates we use are a year out, some are two years out, which means the program will be mostly dead in less than two years. Of course, I could be wrong, since I’m only a novice programmer and they’re the professionals. My first unsettling code experience was as an intern for a major online retailer. I was testing their ad referrals.
The ads didn’t pay on click, but the way it was supposed to work was: if a new user created an account from your ad click, you’d get a dollar and 5 percent of their purchase for the first seven days. If it was an existing user who added anything to their cart or purchased anything during that session, you’d get 5 percent too. The thing is, no matter how hard I tried, I couldn’t replicate the first scenario. No commission was ever paid on sales outside of the initial session for new accounts.
As a lowly intern, my job was to file a bug report. But because I was a giant nerd, I went looking at the code to find the bug myself and submit a report saying, “This function here is bad. ” I’d done that before, and I really wanted to make a good impression so I could turn the internship into a real job after college. Well, the thing was, there was no code for tracking referrals past the initial session at all.
Only users who clicked the link and bought something in that session got referral fees. No logic existed for cart additions or purchases later, and nothing existed to pay for the supposed seven days of purchases. The company was massively underpaying advertisers, and it clearly wasn’t an accident. I handed my findings to my boss, who said she’d follow up on it.
Needless to say, nothing got fixed. A sysadmin friend of mine found a dead man’s switch once. If it detected that a particular account was disabled, it was set to redirect the backups to another location in a way that they’d keep reporting as successful, wait a week, then wipe the file server before deleting itself. It was put there by a former IT consultant as insurance, I guess.
Someone new takes over, and a week later everything explodes. The new guy can’t fix it, so they call the old consultant back in, and he heroically saves the day. Too bad for him, he’d been fired literally years before. The dumb thing misspelled his own account name, so the script had been patiently waiting for a non-existent account to be disabled.
Whoops. I was a digital forensics student, and I saw some wild programs in my malware class. One of my favorites was designed to read the language setting of the victim machine. If it was Japanese, the malware uninstalled itself.
If it was English or almost any other language, it displayed an ominous message like, “You’re a lucky one. ” If it was Chinese, it tried to brick the computer. I never found out the story behind that one, but I feel like there was one. That’s some targeted rage.
One of the more vicious ones I analyzed was designed to perpetuate itself, then wait for around two weeks before actually attacking. My official conclusion was that it waited to give the user time to grow complacent in case they suspected an infection, and it also obscured the actual infection vector by letting the trail go cold. I always thought there was something sinister about a virus that exploits people’s desire to find nothing wrong. Back in the Windows 3.
1 days, I wrote a program that would open every DLL in the Windows folder for writing, then close them, essentially making every DLL zero bytes in length. Anything loaded into memory would still work fine, but anything that wasn’t was horribly screwed. It trashed Windows completely and required a reinstall. You could never pull that off today without a user clicking “OK” on a dialog box a million times.
I wrote it just to see if it would work, and it did. A few friends took that thing without my knowledge at the time and ran it on display computers at RadioShack. I’m sure it created a very bad day for those poor employees. Back in the heyday of Second Life, I was part of a fairly interesting group called WHat, and later another group called V5, quite a fair bit before the 4chan crowd descended.
I made a few different malicious pieces of code that harmed the platform. One was called Cool Shoes, another was called Exitala, and there was an unnamed recursive object unpacker. Cool Shoes was just a highly mutilated torus, duplicated and linked together with slightly different rotations, so it had an increased polygon count and a normals issue that would put it beneath the geometry of the ground. My improvement was to put a small bit of code on each that would change the color and orientation of the textures to force each polygon to read row data as fast as possible.
That changed the object from slowing people down to outright crashing their graphics card processor and eventually causing absurd memory usage. I avoided a similar fate by turning off all rendering outside of the interface element edit. And I used a mostly transparent texture that was hooked into the rendering system, so unless you disabled everything but the interface, you’d instantly get hit by it and be unable to investigate the source. Exitala was a slightly different beast.
Second Life being an adult game had some enterprising users who set up an adult avatar adjustment product. In short, they sold fake bits for your fake self. I reverse engineered their product to figure out the protocol it used to talk between parts and wrote a script to hijack their virtual bits. I don’t think I’ve ever seen something quite so humorous as a hundred virtual people going stiff as a board and having fake orgasms in a public PG-rated area.
I’m pretty sure that got quite a few people banned. Of all the things I wrote, though, the most impactful was probably the unnamed recursive object unpacker. It was essentially virtual gray goo. One object that contained a copy of itself was placed inside a launcher.
It would then spawn that copy repeatedly and give each child a copy of itself, and those children would go forth and do likewise. A friend of mine named Groove and Steam Corvin asked for a copy for a project, and he added a couple things. After all the children were spawned, the original objects would make themselves physical and apply an impulse to themselves while making an obnoxious sound. This resulted in over two hundred servers getting firewalled or often crashed because I transmitted the source in a back-channel messenger.
They never discovered how he learned it or who he learned it from. The original intent of the script was to make an unobtrusive listening device that would circumvent object permissions in a location. Temporary objects could still be rezzed even on parcels that disallowed permanent objects. Such objects would last at least thirty seconds and at most two minutes.
By making my objects ping-pong between copies every thirty seconds, it circumvented the limits, allowing me to spy on people remotely. I was later deservedly banned for an unrelated event involving giant virtual dog penises. In hindsight, being such a little jerk was a really stupid move, as was provoking the person who owned the plot next to my store. Those virtual dog penises made me over thirty grand in real money over the course of a few years.
Furry stuff sells, I guess. One guy I worked with was a real knob, so I wrote a script and hid it in the terminal server session startup of each desk supervisor. Every time they logged in, it would change a specific user’s name from Steven Lee to Steven Rebecca Lee. The only time it was noticeable was when they looked at the Start menu on a Windows XP or older machine, and it drove him insane.
He’d send an IT request to get it fixed, someone would fix it, and by the next time he started his shift, it was back. I didn’t take much care to hide that I had written the script, so either the IT admin team was awful or they never looked at the root cause of the issue. There was also the time in sixth form when I wrote a few little apps that were perhaps best described as irritating, although one may have been a little malicious. One was an infinite while loop that printed the bell character to the system.
When you ran it, the computer would constantly beep. With a normal alphanumeric character, you could easily break out of the program, but with the beep character you couldn’t. My theory was that it took longer for the speaker to produce the beep than it took for the computer to print it. The only way out of it was to reboot the computer.
Another program would run and just sit there, waiting for ten minutes to an hour before opening and closing the CD drive. It would then halve that time and do it again, and halve it again until it was opening every minute. The program was hidden in Windows as Explorer, so you weren’t really able to close it easily. Then there was one on par with going to the furthest extreme cell in Excel and typing a full stop.
When opened, it would send hundreds of blank pages to the printer. Not usually a problem, but when you were in an environment that charged people per printout on a print account system, it would cause real irritation. And the most malicious one: a program that would copy the login page when you locked your computer. When you typed your password in and hit enter, it would close, making it look like you had unlocked your machine.
In reality, though, it would send your password to the printer. The moral of that one is, lock your computers, people. A colleague of mine was a knob, and I wanted to mess with him. I wrote a script and hid it in the terminal server session startup of each desk supervisor.
Every time they logged in, it would change a specific user’s name in the system from Steven Lee to Steven Rebecca Lee. The only time it was noticeable was when they looked at the Start menu on an older Windows machine, and it drove him insane. He’d send an IT request to fix it, someone would fix it, and by the next time he started his shift, it was back. I didn’t take much care to hide that I had written the script, so either the IT admin team was awful or they never looked at the root cause of the issue.
I was a sysadmin doing testing on a government contracted website after a recent code push from our developers. We were getting ready to send out emails to 600 users, one of our biggest groups to use the site at that time. I was the one sending the email, thankfully with my boss looking over my shoulder. A message popped up something along the lines of, “This will send 1,000 plus emails.
Do you want to continue? ” I asked my boss, and he said yes, since the number was close to 600 and some users would receive multiple emails for different tasks. Emails sent. The next morning, our helpdesk was bombarded with emails and phone calls regarding spam emails sent from our system.
Apparently the code was either missing something or had an addition in the line that generates the email recipients, and every subsequent email sent to the next user in the list appended all prior recipients. The first user received 600, the second received 599, and down the line it went. The higher-ups of the program were far from happy, since we were still building a user base and had just scared off the largest group of users we were trying to get into the system. In college, I had five group projects with the same guy, let’s call him Josh, because that was his name.
We had 90 percent of the same classes and a club together for the last year. The short story is that he didn’t have a line of code in our 100-plus hour senior project, and I had just watched him revert all of my contributions to another class’s project five minutes before we were presenting it at the tech school day, where we were also doing the senior project and supposed to have booths next to each other so we could work both. But someone, Josh, forgot to submit that booth to be set up. He had also given the incorrect phone hash to a classmate on the other project who tried to call me all night, wondering why I wasn’t responding.
It was the other guy’s fault for never emailing me or knocking on my door, because he had all the info to do any of that. Anyways, the code I later committed to the senior project was about twenty lines in our AI robot, who gave a spiel about how cool our department was to recruiting students. Except now it had about four minutes of also talking about how Josh did nothing for the project and was horribly incompetent. I won’t repeat the profanity.
But well after grades and stuff were posted, he called me months later, asking how to run the program. I made sure he had the latest version when he did. Fun little thing for the next class to clean up. I remember playing with Windows batch coding as a kid and accidentally made an automatic starting script with a loop that kept launching PowerShell and did some weird stuff to the screen.
The loop repeated so many times my screen looked like a gateway to hell. After 26 windows crashed with the error, I couldn’t do anything. The only solution was to unplug the computer. Next time it booted, the script started again.
The error was so disturbing I was afraid to boot the computer again. Of course, 14-year-old me never heard of safe boot. I’ve been using Debian ever since. One time I found a bit of code in Ada that called a C function to bypass privacy and modify the internals of an object directly.
It was a hack to change something in the processing flow instead of weaving the new functionality in. He waited until the processing was done and shoved the desired results in. I was tasked with a total rewrite where the outputs had to match the legacy code. Because the hack was post-processing, I couldn’t make it bit perfect unless I emulated the hack.
My PM made me do it. Not really that malicious, just annoying. This will probably be the most computer illiterate comment here, but I swear on my life it’s true. When I was 10, I took a basic programming course at the local college over the summer.
The Apple desktop was pretty new. That class took us all the way into Hi-Res graphics. When it came time to register for sixth grade, they offered an intro to computers course with programming on an Apple. My first day, I got in and turned on the computer, figured I’d screw around and show off to the instructor, and typed the beautiful two lines of code that every computer nerd loved to mess with people with: ten print “whatever,” twenty go to ten.
The instructor was totally computer illiterate and had no clue how to make it stop. I did this a couple days a week for the entire course. She never did know what was happening.